Courseiva
Security and Compliance →easyMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company has an Amazon RDS for MySQL database that stores sensitive data. The security team requires encryption at rest and in transit. Which combination of options meets these requirements?

⚠ Common exam trap

DOP-C02 often tests the distinction between encryption at rest and in transit — candidates pick network isolation (private subnet, VPC peering) or client-side KMS encryption, missing that RDS encryption at rest plus SSL enforcement is the correct combination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable encryption at rest on the RDS instance and enforce SSL connections

Enabling encryption at rest on the RDS instance (via KMS) and enforcing SSL/TLS connections satisfies both requirements: encryption at rest protects data on disk, and SSL enforcement encrypts data in transit between the client and the database. RDS supports encryption at rest through KMS keys and SSL enforcement via parameter group settings (e.g., require_secure_transport for MySQL).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Certificate Manager to issue a certificate for the RDS instance

    Why it's wrong here

    AWS Certificate Manager (ACM) issues public/private certificates for use with load balancers, CloudFront, or API Gateway, but ACM certificates cannot be installed directly on an Amazon RDS instance. Even if a certificate were used to secure the client-to-database connection, TLS/SSL only encrypts data in transit and does nothing to protect the database files, snapshots, or backups while they are stored on disk. Therefore, this approach does not provide the required encryption at rest.

  • ✗

    Place the RDS instance in a private subnet and use VPC peering

    Why it's wrong here

    Placing the RDS instance in a private subnet and using VPC peering only changes network topology and routing; it does not add any encryption layer. VPC peering traffic flows across the AWS network but is not encrypted by VPC peering itself, and a private subnet simply restricts direct Internet access. Database files remain unencrypted on disk, so this option fails to meet both the at-rest encryption requirement and the in-transit encryption requirement.

  • ✓

    Enable encryption at rest on the RDS instance and enforce SSL connections

    Why this is correct

    Enabling RDS encryption at rest encrypts the underlying storage, automated backups, snapshots, and read replicas using AWS KMS AES-256 encryption, satisfying the data-at-rest requirement. Enforcing SSL connections (for example, by setting rds.force_ssl=1 or requiring ssl-mode in the client) encrypts data between the application and the database, covering data in transit. Note that enabling encryption at rest on an existing unencrypted MySQL instance requires restoring from an encrypted snapshot rather than modifying the instance in place, but together these controls fully address the stated security need.

  • ✗

    Use AWS KMS to encrypt the database before inserting data and decrypt on read

    Why it's wrong here

    Calling AWS KMS from your application to encrypt values before inserting them and decrypting them after reading is client-side encryption, not native RDS encryption at rest. This approach leaves the database engine, transaction logs, backups, and snapshots unencrypted, and it forces every query and application code path to manage encryption keys and data transformations. AWS KMS is the key manager used by RDS encryption at rest, but the RDS service itself must be configured to encrypt the data files, not your application.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.